Re: #22

Sam Hartman <[email protected]> Tue, 08 Feb 2005 16:24:52 -0500
Newsgroups gmane.ietf.kink
Message-ID <[email protected]>
>>>>> "Michael" == Michael Thomas <[email protected]> writes:

    Michael> Well, it's pretty simple really: when you get tickets
    Michael> from the KDC, they aren't protected by PFS so using PFS
    Michael> later is pretty questionable. It's not useless, but it's
    Michael> not any huge win either. Until Kerberos itself supports
    Michael> PFS, people deploying KINK really ought not get worked up
    Michael> into a lather about turning on PFS to improve security
    Michael> since it's doesn't to any great degree.

I'm confused.  I thought the point of PFS was to make it impossible to
recover session data .  How does the fact that the KDC does not do PFS
decrease the value of PFS for Kink?